CVE-2022-0694: vulnerability in Advanced Booking Calendar
Advanced Booking Calendar < 1.7.0 - Unauthenticated SQL Injection
Published · Updated
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.8%
exploitation probability
1.8%top 22% of all CVEs
observed exploitation
nono source reports it
The Advanced Booking Calendar WordPress plugin before 1.7.0 does not validate and escape the calendar parameter before using it in a SQL statement via the abc_booking_getSingleCalendar AJAX action (available to both unauthenticated and authenticated users), leading to an unauthenticated SQL injection
Affected products
Unknown · Advanced Booking CalendarRelated CVEs — Advanced Booking Calendar
In the same product, most dangerous first.
CVE-2022-1007—Advanced Booking Calendar < 1.7.1 - Reflected Cross-Site ScriptingEPSS 1.9%CVE-2022-1006—Advanced Booking Calendar < 1.7.1 - Admin+ SQLiEPSS 1.5%CVE-2021-24225—Advanced Booking Calendar < 1.6.7 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2021-24232—Advanced Booking Calendar < 1.6.8 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.6%